HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
Carnival Corporation Ltd.
bd_a5d9e7922483dc25 · schema v1 · pii pii-v1
Full breach record for Carnival Corporation Ltd. →Carnival Corporation & PLC reported a data breach affecting guest information between April 11 and July 23, 2019. An unsanctioned third party gained unauthorized access to employee email accounts containing personal data including names, SSNs, government IDs, credit card info, and health data. The company engaged forensic experts, notified law enforcement, and offered credit monitoring services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_7f27ae5a99b9692fDelaware State AGfiled 2020-03-02(1d gap)Verified
- bd_ab0adfeb7caa7d91South Carolina State AGfiled 2020-03-06(3d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-187901
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 3, 2020
- Raw hash
- 5bba5b2dd7f8b43d75f57fb64678c7d62aa8cb95f1bbc1236bf62ca9cae38b49
Reporting entity
- Name
- Carnival Corporation Ltd.norm: carnival
- Domain
- carnivalcorp.com
Victim entity
- Name
- Carnival Corporation Ltd.norm: carnival
- Domain
- carnivalcorp.com
Incident
- Discovered
- May 31, 2019
- Materiality determined
- Jun 1, 2020
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 40 weeks(277 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.